{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:28c21eac-0a3d-5270-87aa-a1b787fe87ea",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat",
      "version": "9.0.100-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:68642dda-23b6-5c8c-80d5-83a9803366d1",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370d34db-e3aa-5817-9be8-3589abd3bae3",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4b9bd36-a00e-5047-bfc2-425e04eb671d",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e00a60d5-da91-511c-96e7-6ed288949c14",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36ac7e47-46af-55ae-8366-109e78ed354d",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be2fa7b5-f5bb-5dac-bac5-1568cce26490",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79025ac7-27e1-5e67-96f2-54c22a4bf14b",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00172d1c-666f-5d38-be12-802724b0293f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:214d2893-d8b3-5243-9b8b-da8516a009ec",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45bd87a5-5c9c-5016-aab6-b75709072a84",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d6096fa-44c3-54f1-aceb-343d43b90112",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd10541c-ddda-5032-9b9e-d81f4116caa3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f9f7d55-7803-52e0-ae31-8ac73904aab0",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ec84323-b116-5554-8a4c-de2d49a9cfd1",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:762db1fc-9d56-533d-bd53-efbec4007355",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a840d270-421f-5290-ba83-b86129f5155f",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57593e45-7685-5577-a0f7-8c75c07125ee",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be38f1c6-6844-5c1c-b4f2-40458eef72c4",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2e1ef1-a6c9-52cd-942c-5cc06d88d7cc",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f0b38e4-426a-56d1-8548-5d49646f2609",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fe0e9ca-6aa4-55d5-9202-06686b5bd1b9",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27925338-e5e0-5ee7-9d90-eeadeafe213b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcfba385-487e-5bb7-9645-24297b11612a",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a3d1c7-edf2-5441-ba6a-119506b2b152",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f39d23-2007-5c5a-a7a4-30267da87a95",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45275ff7-c3de-5ae1-959f-adb843286a4a",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97e162ea-56ca-5de1-89eb-a20fcfda6131",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ddb7527-90ab-5469-9b29-2b982a7bbca4",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f41895-63e5-5c08-bfbe-4fd06b385aa4",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9890f7-6deb-5c70-b088-4c2318f788d9",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4c32f93-6cfa-5f8f-8a6a-836ee165b05c",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a072a612-7e4c-5e63-a4bb-7c52ac8f2215",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852ace24-e274-584a-b07f-277424ca457b",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90b86881-e209-5e22-ba10-3b421dda71a3",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f79d3e-5706-5ebe-a0e9-930162cf6376",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d02059-d521-5308-8e3e-c17f0ed26b69",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.100-tuxcare.3"
    }
  ]
}